Content
63%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, technique-rich body with copy-paste payloads, tool commands, and both exploit and remediation code — its command coverage is essentially complete. Its weaknesses are verbosity (it explains traversal fundamentals and HTTP/filesystem prerequisites Claude already knows, and duplicates payload/target listings in a Quick Reference) and a total absence of progressive disclosure: ~480 lines of catalogs inlined into SKILL.md with no reference files.
Suggestions
Move the Phase 5-6 target-file catalogs, the encoding-variant tables, and the Quick Reference into references/ files (e.g. references/linux-targets.md, references/windows-targets.md, references/payloads.md) and keep a 10-20 line overview plus one-line links in SKILL.md.
Delete or compress the padding Claude doesn't need: the 'Attack principle' bullets, the 'Impact' prose, the Prerequisites section (HTTP structure, filesystem layout), and the Quick Reference tables that duplicate Phases 3-6.
Add explicit validation checkpoints between steps, e.g. 'Confirm a hit by checking the response for `root:x:0:0` before proceeding to escalation', and wire the Troubleshooting table entries back to the phase where each failure occurs.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~480-line body repeatedly explains concepts Claude already knows — 'Path traversal occurs when applications use user input to construct file paths', '`../` sequence moves up one directory', prerequisite lists like 'HTTP request/response structure' and 'Linux and Windows filesystem layout'. It is also internally redundant: the Quick Reference tables (payloads, target files, encoding variants) restate material already given in Phases 3-6. This matches anchor 2 ('noticeably verbose; several unnecessary explanations or padded sections'); it is above 1 because the payload/command content itself is dense rather than padded prose, but below 3 because the padding and duplication are substantial, not incidental. | 2 / 5 |
Actionability | The content is copy-paste ready throughout: concrete curl invocations with payloads, runnable ffuf/wfuzz command lines with real wordlist paths (LFI-Jhaddix.txt), null-byte/encoding/Unicode bypass payloads, PHP wrapper URLs, and working prevention code in both PHP and Python. The common cases (Linux and Windows targets, GET parameters, cookie-based templates, automation, RCE escalation) are all covered with specific examples. It barely misses nothing executable — the Burp Suite section is numbered GUI steps and Phase 9 is comment-style methodology, but these are inherently instructional and concrete. | 5 / 5 |
Workflow Clarity | The skill is organized as a clear ten-phase pipeline (understand → identify traversal points → basic exploitation → bypasses → Linux/Windows targets → automation → RCE escalation → methodology → prevention), and Phase 9 restates it as an ordered 8-step testing sequence. Most checkpoints are present: Burp filtering 'by size/content for success', ffuf `-mc 200`, wfuzz `--hc 404`, and a Troubleshooting table with failure→remedy mappings. It falls short of 5 because verification of a successful read (e.g., confirming `root:` lines for /etc/passwd) is left implicit rather than stated as an explicit validation step. The batch-fuzzing operations do carry response filters, so the batch-operation cap at 3 is not triggered. | 4 / 5 |
Progressive Disclosure | There is no references/ directory at all — the entire catalog lives inline in a single ~480-line SKILL.md, including large target-file listings (Phases 5-6), payload tables, and encoding variants that clearly belong in separate reference files loaded on demand. Section headers and tables do provide real structure, which lifts it above anchor 2 ('no section headers, content inlined'), but it squarely matches anchor 3: structure exists, yet content that should be split into reference files is inline and nothing is offloaded. It cannot score 4+ because there are no well-signaled one-level-deep references to move detail behind. | 3 / 5 |
Total | 14 / 20 Passed |